|
AWS IAM AccessDenied Discovery Events
|
AWS CloudTrail
|
T1580
|
Anomaly
|
Suspicious Cloud User Activities
|
2026-05-13
|
|
Kubernetes Scanning by Unauthenticated IP Address
|
Kubernetes Audit
|
T1046
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
AWS IAM Successful Group Deletion
|
AWS CloudTrail DeleteGroup
|
T1069.003
T1098
|
Hunting
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
Amazon EKS Kubernetes cluster scan detection
|
|
T1526
|
Hunting
|
Kubernetes Scanning Activity
|
2026-05-13
|
|
Azure AD AzureHound UserAgent Detected
|
Azure Active Directory NonInteractiveUserSignInLogs, Azure Active Directory MicrosoftGraphActivityLogs
|
T1087.004
T1526
|
TTP
|
Azure Active Directory Privilege Escalation, Compromised User Account
|
2026-05-13
|
|
AWS Bedrock High Number List Foundation Model Failures
|
AWS CloudTrail
|
T1580
|
TTP
|
AWS Bedrock Security
|
2026-05-13
|
|
Kubernetes Suspicious Image Pulling
|
Kubernetes Audit
|
T1526
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
GCP Kubernetes cluster pod scan detection
|
|
T1526
|
Hunting
|
Scattered Lapsus$ Hunters, Kubernetes Scanning Activity
|
2026-05-13
|
|
ASL AWS IAM AccessDenied Discovery Events
|
ASL AWS CloudTrail
|
T1580
|
Anomaly
|
Suspicious Cloud User Activities
|
2026-05-13
|
|
Azure AD Service Principal Enumeration
|
Azure Active Directory MicrosoftGraphActivityLogs
|
T1087.004
T1526
|
TTP
|
Azure Active Directory Privilege Escalation, Compromised User Account
|
2026-05-13
|
|
AWS IAM Assume Role Policy Brute Force
|
AWS CloudTrail
|
T1110
T1580
|
TTP
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
ASL AWS IAM Successful Group Deletion
|
ASL AWS CloudTrail
|
T1069.003
T1098
|
Hunting
|
AWS IAM Privilege Escalation
|
2026-05-13
|
|
AWS Password Policy Changes
|
AWS CloudTrail GetAccountPasswordPolicy, AWS CloudTrail UpdateAccountPasswordPolicy, AWS CloudTrail DeleteAccountPasswordPolicy
|
T1201
|
Hunting
|
AWS IAM Privilege Escalation, Compromised User Account
|
2026-05-13
|
|
AWS Excessive Security Scanning
|
AWS CloudTrail
|
T1526
|
TTP
|
AWS User Monitoring
|
2026-05-13
|
|
ASL AWS IAM Assume Role Policy Brute Force
|
ASL AWS CloudTrail
|
T1110
T1580
|
TTP
|
AWS IAM Privilege Escalation, Scattered Lapsus$ Hunters
|
2026-05-13
|
|
Kubernetes Scanner Image Pulling
|
|
T1526
|
TTP
|
Dev Sec Ops
|
2026-05-13
|
|
AWS High Number Of Failed Authentications For User
|
AWS CloudTrail ConsoleLogin
|
T1201
|
Anomaly
|
Compromised User Account, AWS Identity and Access Management Account Takeover
|
2026-05-13
|
|
Amazon EKS Kubernetes Pod scan detection
|
|
T1526
|
Hunting
|
Kubernetes Scanning Activity
|
2026-05-13
|
|
Kubernetes Access Scanning
|
Kubernetes Audit
|
T1046
|
Anomaly
|
Kubernetes Security
|
2026-05-13
|
|
Elevated Group Discovery with PowerView
|
Powershell Script Block Logging 4104
|
T1069.002
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Large Number of Computer Service Tickets Requested
|
Windows Event Log Security 4769
|
T1078
T1135
|
Anomaly
|
Active Directory Lateral Movement, Active Directory Privilege Escalation
|
2026-07-05
|
|
Windows Query Registry Browser List Application
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
China-Nexus Threat Activity, Salt Typhoon, SnappyBee, RedLine Stealer
|
2026-05-13
|
|
Get-DomainTrust with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1482
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Get WMIObject Group Discovery with Script Block Logging
|
Powershell Script Block Logging 4104
|
T1069.001
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Administrative Shares Accessed On Multiple Hosts
|
Windows Event Log Security 5145, Windows Event Log Security 5140
|
T1135
|
TTP
|
Active Directory Lateral Movement, Active Directory Privilege Escalation
|
2026-05-13
|
|
Windows Account Discovery for None Disable User Account
|
Powershell Script Block Logging 4104
|
T1087.001
|
Hunting
|
CISA AA23-347A
|
2026-05-13
|
|
Windows PowerShell Invoke-RestMethod IP Information Collection
|
Powershell Script Block Logging 4104
|
T1016
T1059.001
T1082
|
Anomaly
|
Water Gamayun
|
2026-05-13
|
|
Windows Find Domain Organizational Units with GetDomainOU
|
Powershell Script Block Logging 4104
|
T1087.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Non Discord App Access Discord LevelDB
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
StealC Stealer, BlankGrabber Stealer, PXA Stealer, Snake Keylogger, Phantom Stealer
|
2026-06-25
|
|
Linux Auditd Virtual Disk File And Directory Discovery
|
Linux Auditd Execve
|
T1083
|
Anomaly
|
Linux Persistence Techniques, Compromised Linux Host, Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Linux Auditd System Network Configuration Discovery
|
Linux Auditd Syscall
|
T1016
|
Anomaly
|
Linux Persistence Techniques, Compromised Linux Host, Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Root Domain linked policies Discovery
|
Powershell Script Block Logging 4104
|
T1087.002
|
Anomaly
|
Industroyer2, Data Destruction, Active Directory Discovery
|
2026-05-13
|
|
Windows Azure PowerShell Module Installation Via PowerShell Script
|
Powershell Script Block Logging 4104
|
T1021.007
T1069.003
T1078
T1098
T1136.003
|
Anomaly
|
Azure Active Directory Account Takeover, Azure Active Directory Privilege Escalation, Azure Active Directory Persistence
|
2026-05-13
|
|
Windows Credentials from Password Stores Chrome LocalState Access
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
Lokibot, Earth Alux, China-Nexus Threat Activity, RedLine Stealer, StealC Stealer, 0bj3ctivity Stealer, Snake Keylogger, Vidar Stealer, NjRAT, Salt Typhoon, Amadey, Phantom Stealer, Meduza Stealer, Warzone RAT, DarkGate Malware, Malicious Inno Setup Loader, BlankGrabber Stealer, SnappyBee, VIP Keylogger, Quasar RAT, Phemedrone Stealer, MoonPeak, Scattered Lapsus$ Hunters, Salat Stealer, Braodo Stealer, PXA Stealer
|
2026-08-14
|
|
Windows Linked Policies In ADSI Discovery
|
Powershell Script Block Logging 4104
|
T1087.002
|
Anomaly
|
Industroyer2, Data Destruction, Active Directory Discovery
|
2026-05-13
|
|
Linux Auditd Kernel Module Enumeration
|
Linux Auditd Syscall
|
T1014
T1082
|
Anomaly
|
XorDDos, Compromised Linux Host, Linux Rootkit
|
2026-05-13
|
|
Linux Auditd Hidden Files And Directories Creation
|
Linux Auditd Execve
|
T1083
|
Anomaly
|
Linux Persistence Techniques, Compromised Linux Host, Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Windows Credential Access From Browser Password Store
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
Earth Alux, China-Nexus Threat Activity, StealC Stealer, 0bj3ctivity Stealer, Snake Keylogger, Salt Typhoon, Phantom Stealer, Meduza Stealer, Scattered Spider, Malicious Inno Setup Loader, BlankGrabber Stealer, SnappyBee, VIP Keylogger, Quasar RAT, MoonPeak, Scattered Lapsus$ Hunters, Salat Stealer, Braodo Stealer, PXA Stealer
|
2026-06-25
|
|
GetWmiObject DS User with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1087.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Hosts File Access
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
BlankGrabber Stealer, Gh0st RAT
|
2026-05-13
|
|
Domain Group Discovery with Adsisearcher
|
Powershell Script Block Logging 4104
|
T1069.002
|
TTP
|
Scattered Lapsus$ Hunters, Active Directory Discovery
|
2026-05-13
|
|
Linux Auditd Whoami User Discovery
|
Linux Auditd Syscall
|
T1033
|
Anomaly
|
QuietVault, Linux Living Off The Land, Linux Privilege Escalation, Linux Persistence Techniques, Compromised Linux Host
|
2026-05-13
|
|
GetDomainController with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1018
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Get DomainUser with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1087.002
|
TTP
|
Active Directory Discovery, CISA AA23-347A
|
2026-05-13
|
|
GetCurrent User with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1033
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
GetAdComputer with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1018
|
Hunting
|
Medusa Ransomware, CISA AA22-320A, Gozi Malware, Active Directory Discovery
|
2026-05-13
|
|
Windows AD Abnormal Object Access Activity
|
Windows Event Log Security 4662
|
T1087.002
|
Anomaly
|
Active Directory Discovery, BlackSuit Ransomware
|
2026-05-13
|
|
GetDomainGroup with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1069.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Credentials from Password Stores Chrome Extension Access
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
Amadey, StealC Stealer, Meduza Stealer, Malicious Inno Setup Loader, BlankGrabber Stealer, RedLine Stealer, 0bj3ctivity Stealer, Phantom Stealer, Phemedrone Stealer, MoonPeak, Vidar Stealer, DarkGate Malware, Braodo Stealer, CISA AA23-347A
|
2026-08-14
|
|
Windows Product Key Registry Query
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
BlankGrabber Stealer
|
2026-05-13
|
|
Windows PowerView AD Access Control List Enumeration
|
Powershell Script Block Logging 4104
|
T1069
T1078.002
|
TTP
|
Rhysida Ransomware, Active Directory Privilege Escalation, Active Directory Discovery
|
2026-05-13
|
|
GetAdGroup with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1069.002
|
Hunting
|
Scattered Lapsus$ Hunters, Active Directory Discovery
|
2026-05-13
|
|
Get-ForestTrust with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1059.001
T1482
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows AD Privileged Object Access Activity
|
Windows Event Log Security 4662
|
T1087.002
|
TTP
|
Active Directory Discovery, BlackSuit Ransomware
|
2026-05-13
|
|
Windows PowerView Unconstrained Delegation Discovery
|
Powershell Script Block Logging 4104
|
T1018
|
TTP
|
Active Directory Kerberos Attacks, Rhysida Ransomware, CISA AA23-347A
|
2026-05-13
|
|
Windows Get-AdComputer Unconstrained Delegation Discovery
|
Powershell Script Block Logging 4104
|
T1018
|
TTP
|
Medusa Ransomware, Active Directory Kerberos Attacks
|
2026-05-13
|
|
Get DomainPolicy with Powershell Script Block
|
Powershell Script Block Logging 4104
|
T1201
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Forest Discovery with GetForestDomain
|
Powershell Script Block Logging 4104
|
T1087.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
GetWmiObject Ds Group with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1069.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Linux Auditd File And Directory Discovery
|
Linux Auditd Execve
|
T1083
|
Anomaly
|
Linux Persistence Techniques, Compromised Linux Host, Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
Get ADUserResultantPasswordPolicy with Powershell Script Block
|
Powershell Script Block Logging 4104
|
T1201
|
TTP
|
Active Directory Discovery, CISA AA23-347A
|
2026-05-13
|
|
Powershell Get LocalGroup Discovery with Script Block Logging
|
Powershell Script Block Logging 4104
|
T1069.001
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Network Share Discovery Via Dir Command
|
Windows Event Log Security 5140
|
T1135
|
Hunting
|
IcedID
|
2026-08-05
|
|
Windows Special Privileged Logon On Multiple Hosts
|
Windows Event Log Security 4672
|
T1021.002
T1087
T1135
|
TTP
|
Active Directory Lateral Movement, Active Directory Privilege Escalation, Compromised Windows Host
|
2026-05-13
|
|
Get ADDefaultDomainPasswordPolicy with Powershell Script Block
|
Powershell Script Block Logging 4104
|
T1201
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Get ADUser with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1087.002
|
Hunting
|
Active Directory Discovery, CISA AA23-347A
|
2026-05-13
|
|
Enumerate Users Local Group Using Telegram
|
Windows Event Log Security 4798
|
T1087
|
TTP
|
XMRig, Water Gamayun, Compromised Windows Host
|
2026-05-13
|
|
Windows Get Local Admin with FindLocalAdminAccess
|
Powershell Script Block Logging 4104
|
T1087.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Find Interesting ACL with FindInterestingDomainAcl
|
Powershell Script Block Logging 4104
|
T1087.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
AdsiSearcher Account Discovery
|
Powershell Script Block Logging 4104
|
T1087.002
|
TTP
|
Active Directory Discovery, Industroyer2, Scattered Lapsus$ Hunters, Data Destruction, CISA AA23-347A
|
2026-05-13
|
|
GetDomainComputer with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1018
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Network Traffic to Active Directory Web Services Protocol
|
Sysmon EventID 3
|
T1069.001
T1069.002
T1087.001
T1087.002
T1482
|
Hunting
|
Windows Discovery Techniques
|
2026-05-13
|
|
Windows PowerView Constrained Delegation Discovery
|
Powershell Script Block Logging 4104
|
T1018
|
TTP
|
Active Directory Kerberos Attacks, Rhysida Ransomware, CISA AA23-347A
|
2026-05-13
|
|
GetNetTcpconnection with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1049
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Cisco NVM - Suspicious Network Connection to IP Lookup Service API
|
Cisco Network Visibility Module Flow Data
|
T1016
T1590.005
|
Anomaly
|
Castle RAT, BlankGrabber Stealer, Cisco Network Visibility Module Analytics
|
2026-07-14
|
|
Windows Credentials from Password Stores Chrome Login Data Access
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
Lokibot, Earth Alux, China-Nexus Threat Activity, RedLine Stealer, StealC Stealer, 0bj3ctivity Stealer, Snake Keylogger, Vidar Stealer, NjRAT, Salt Typhoon, Amadey, Phantom Stealer, Meduza Stealer, Warzone RAT, DarkGate Malware, Malicious Inno Setup Loader, BlankGrabber Stealer, SnappyBee, VIP Keylogger, Quasar RAT, Phemedrone Stealer, MoonPeak, Scattered Lapsus$ Hunters, Salat Stealer, Braodo Stealer, PXA Stealer
|
2026-08-14
|
|
Windows WinPEAS PowerShell Script Execution
|
Powershell Script Block Logging 4104
|
T1007
T1016
T1033
T1082
T1590
T1592.002
T1592.004
T1615
|
TTP
|
Windows Post-Exploitation
|
2026-05-13
|
|
Windows Software Discovery Via PowerShell
|
Powershell Script Block Logging 4104
|
T1012
T1059.001
T1518
|
Anomaly
|
Windows Discovery Techniques
|
2026-05-13
|
|
Windows Account Discovery for Sam Account Name
|
Powershell Script Block Logging 4104
|
T1087
|
Anomaly
|
CISA AA23-347A
|
2026-05-13
|
|
Windows Domain Account Discovery Via Get-NetComputer
|
Powershell Script Block Logging 4104
|
T1087.002
|
Anomaly
|
CISA AA23-347A
|
2026-05-13
|
|
GetWmiObject Ds Computer with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1018
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows File Share Discovery With Powerview
|
Powershell Script Block Logging 4104
|
T1135
|
TTP
|
Active Directory Discovery, Active Directory Privilege Escalation
|
2026-05-13
|
|
Remote System Discovery with Adsisearcher
|
Powershell Script Block Logging 4104
|
T1018
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows ConvertTo-AADIntBackdoor Execution Via PowerShell Script
|
Powershell Script Block Logging 4104
|
T1071.001
T1078
T1212
T1482
|
TTP
|
Azure Active Directory Account Takeover, Azure Active Directory Privilege Escalation, Azure Active Directory Persistence
|
2026-05-13
|
|
SchCache Change By App Connect And Create ADSI Object
|
Sysmon EventID 11
|
T1087.002
|
Anomaly
|
BlackMatter Ransomware
|
2026-05-13
|
|
Windows Query Registry UnInstall Program List
|
Windows Event Log Security 4663
|
T1012
|
Anomaly
|
StealC Stealer, Meduza Stealer, Vidar Stealer, RedLine Stealer
|
2026-08-14
|
|
GetLocalUser with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1059.001
T1087.001
|
Hunting
|
Malicious PowerShell, Active Directory Discovery
|
2026-05-13
|
|
Windows Account Discovery With NetUser PreauthNotRequire
|
Powershell Script Block Logging 4104
|
T1087
|
Hunting
|
CISA AA23-347A
|
2026-05-13
|
|
Linux Auditd Database File And Directory Discovery
|
Linux Auditd Execve
|
T1083
|
Anomaly
|
Linux Persistence Techniques, Compromised Linux Host, Linux Living Off The Land, Linux Privilege Escalation
|
2026-05-13
|
|
User Discovery With Env Vars PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1033
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
GetWmiObject User Account with PowerShell Script Block
|
Powershell Script Block Logging 4104
|
T1059.001
T1087.001
|
Hunting
|
Malicious PowerShell, Active Directory Discovery, Winter Vivern
|
2026-05-13
|
|
Cisco Secure Firewall - Blocked Connection
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1018
T1046
T1110
T1203
T1595.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco Secure Firewall - Repeated Blocked Connections
|
Cisco Secure Firewall Threat Defense Connection Event
|
T1018
T1046
T1110
T1203
T1595.002
|
Anomaly
|
Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
ESXi VM Discovery
|
VMWare ESXi Syslog
|
T1673
|
TTP
|
China-Nexus Threat Activity, ESXi Post Compromise, Black Basta Ransomware
|
2026-05-13
|
|
Cisco ASA - Reconnaissance Command Activity
|
Cisco ASA Logs
|
T1082
T1590.001
T1590.005
|
Anomaly
|
Suspicious Cisco Adaptive Security Appliance Activity
|
2026-05-13
|
|
ESXi System Information Discovery
|
VMWare ESXi Syslog
|
T1082
|
TTP
|
ESXi Post Compromise, Black Basta Ransomware
|
2026-05-13
|
|
Okta Unauthorized Access to Application
|
Okta
|
T1087.004
|
Anomaly
|
Okta Account Takeover
|
2026-05-13
|
|
Okta Multiple Failed Requests to Access Applications
|
Okta
|
T1538
T1550.004
|
Hunting
|
Okta Account Takeover
|
2026-05-13
|
|
Cisco IOS XE Reconnaissance Command Activity
|
Cisco IOS Logs
|
T1016
T1082
T1590
|
Anomaly
|
Salt Typhoon
|
2026-05-20
|
|
Cisco IOS XE Remote Access Probe Burst
|
Cisco IOS Logs
|
T1018
T1021.004
T1046
|
Anomaly
|
Salt Typhoon
|
2026-05-20
|
|
Okta IDP Lifecycle Modifications
|
Okta
|
T1087.004
|
Anomaly
|
Suspicious Okta Activity
|
2026-05-13
|
|
Cisco ASA - Packet Capture Activity
|
Cisco ASA Logs
|
T1040
T1557
|
Anomaly
|
ArcaneDoor, Suspicious Cisco Adaptive Security Appliance Activity
|
2026-05-13
|
|
Splunk Authentication Token Exposure in Debug Log
|
|
T1654
|
TTP
|
Splunk Vulnerabilities
|
2026-06-24
|
|
ESXi Bulk VM Termination
|
VMWare ESXi Syslog
|
T1499
T1529
T1673
|
TTP
|
ESXi Post Compromise, Black Basta Ransomware
|
2026-09-08
|
|
Detect attackers scanning for vulnerable JBoss servers
|
|
T1082
T1133
|
TTP
|
SamSam Ransomware, JBoss Vulnerability
|
2026-05-13
|
|
Windows Chromium Process with Disabled Extensions
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1497
|
Anomaly
|
Browser Hijacking
|
2026-05-13
|
|
GetLocalUser with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1087.001
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Domain Account Discovery with Wmic
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1087.002
|
TTP
|
Interlock Ransomware, Active Directory Discovery
|
2026-05-13
|
|
Windows Admin Permission Discovery
|
Sysmon EventID 11
|
T1069.001
|
Anomaly
|
NjRAT
|
2026-05-13
|
|
GetCurrent User with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1033
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Local Account Discovery With Wmic
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1087.001
|
Hunting
|
Scattered Lapsus$ Hunters, Active Directory Discovery
|
2026-05-13
|
|
Domain Group Discovery With Wmic
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.002
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Suspect Process With Authentication Traffic
|
Sysmon EventID 3
|
T1087.002
T1204.002
|
Anomaly
|
Active Directory Discovery
|
2026-05-13
|
|
Headless Browser Usage
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1497
T1564.003
|
Anomaly
|
Browser Hijacking, Forest Blizzard, Phantom Stealer
|
2026-06-25
|
|
Windows SOAPHound Binary Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.001
T1069.002
T1087.001
T1087.002
T1482
|
TTP
|
Compromised Windows Host, Windows Discovery Techniques
|
2026-05-13
|
|
Advanced IP or Port Scanner Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1046
T1135
|
Anomaly
|
Windows Defense Evasion Tactics
|
2026-05-13
|
|
Windows Wmic Network Discovery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1082
|
Anomaly
|
LAMEHUG
|
2026-05-13
|
|
Windows EventLog Recon Activity Using Log Query Utilities
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1654
|
Anomaly
|
BlankGrabber Stealer, Windows Discovery Techniques
|
2026-05-13
|
|
Get-DomainTrust with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1482
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Chromium Process Launched with Logging Disabled
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1497
|
Anomaly
|
Browser Hijacking
|
2026-05-13
|
|
Windows Ldifde Directory Object Behavior
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.002
T1105
|
TTP
|
Volt Typhoon
|
2026-05-13
|
|
GetDomainComputer with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1018
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
NLTest Domain Trust Discovery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1482
|
TTP
|
Active Directory Discovery, Qakbot, Storm-0501 Ransomware, Cleo File Transfer Software, Domain Trust Discovery, Ryuk Ransomware, Medusa Ransomware, IcedID, Rhysida Ransomware
|
2026-05-13
|
|
System User Discovery With Query
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1033
|
Hunting
|
Medusa Ransomware, Active Directory Discovery
|
2026-05-13
|
|
Potential System Network Configuration Discovery Activity
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1016
|
Anomaly
|
Unusual Processes
|
2026-05-13
|
|
Windows PsTools Recon Usage
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1018
T1046
T1082
|
Anomaly
|
Compromised Windows Host
|
2026-05-13
|
|
Windows System Time Discovery W32tm Delay
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1124
|
Anomaly
|
DarkCrystal RAT
|
2026-05-13
|
|
GetDomainController with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1018
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
GetWmiObject DS User with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1087.002
|
Anomaly
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Group Discovery Via Net
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.001
T1069.002
|
Hunting
|
Windows Post-Exploitation, Microsoft WSUS CVE-2025-59287, Active Directory Discovery, Graceful Wipe Out Attack, SolarWinds WHD RCE Post Exploitation, Cleo File Transfer Software, Windows Discovery Techniques, Azorult, Volt Typhoon, Prestige Ransomware, Medusa Ransomware, IcedID, Rhysida Ransomware
|
2026-05-13
|
|
Windows System Network Config Discovery Display DNS
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1016
|
Anomaly
|
Medusa Ransomware, Windows Post-Exploitation, Water Gamayun, Prestige Ransomware
|
2026-05-13
|
|
Get DomainPolicy with Powershell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1201
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Netspy Network Scanner Execution
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1018
T1595
|
Anomaly
|
Network Discovery, Windows Discovery Techniques
|
2026-05-13
|
|
Domain Controller Discovery with Nltest
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1018
|
TTP
|
Active Directory Discovery, Starland RAT Campaign, NetSupport RMM Tool Abuse, BlackSuit Ransomware, Medusa Ransomware, Rhysida Ransomware, CISA AA23-347A
|
2026-07-20
|
|
Get ADUserResultantPasswordPolicy with Powershell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1201
|
TTP
|
Active Directory Discovery, CISA AA23-347A
|
2026-05-13
|
|
Detect AzureHound File Modifications
|
Sysmon EventID 11
|
T1069.001
T1069.002
T1087.001
T1087.002
T1482
|
TTP
|
Windows Discovery Techniques
|
2026-05-13
|
|
PowerShell Get LocalGroup Discovery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.001
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Network Connection Discovery With Netstat
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1049
|
Hunting
|
Windows Post-Exploitation, Active Directory Discovery, Qakbot, PlugX, Volt Typhoon, Prestige Ransomware, Medusa Ransomware, CISA AA22-277A, CISA AA23-347A
|
2026-05-13
|
|
Linux Root Execution of id
|
Sysmon for Linux EventID 1
|
T1033
|
Anomaly
|
Linux Persistence Techniques, Linux Post-Exploitation, Linux Privilege Escalation
|
2026-07-08
|
|
Windows Process Commandline Discovery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1057
|
Hunting
|
CISA AA23-347A
|
2026-05-13
|
|
Windows System Remote Discovery With Query
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1033
|
Hunting
|
Medusa Ransomware, Active Directory Discovery
|
2026-05-13
|
|
Get DomainUser with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1087.002
|
TTP
|
Active Directory Discovery, CISA AA23-347A
|
2026-05-13
|
|
Windows Time Based Evasion via Choice Exec
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1497.003
|
Anomaly
|
0bj3ctivity Stealer, VIP Keylogger, Snake Keylogger
|
2026-05-13
|
|
Get ADDefaultDomainPasswordPolicy with Powershell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1201
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
GetAdComputer with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1018
|
Hunting
|
Medusa Ransomware, Active Directory Discovery
|
2026-05-13
|
|
Check Elevated CMD using whoami
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1033
|
TTP
|
FIN7
|
2026-05-13
|
|
Linux System Network Discovery
|
Sysmon for Linux EventID 1, Osquery Results
|
T1016
|
Anomaly
|
Industroyer2, Data Destruction, Network Discovery, VoidLink Cloud-Native Linux Malware
|
2026-05-13
|
|
Windows Wmic Systeminfo Discovery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1082
|
Anomaly
|
LAMEHUG, BlankGrabber Stealer, Lotus Blossom Chrysalis Backdoor
|
2026-05-13
|
|
Windows AdFind Exe
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1018
|
TTP
|
Graceful Wipe Out Attack, Domain Trust Discovery, BlackSuit Ransomware, NOBELIUM Group, IcedID
|
2026-05-13
|
|
User Discovery With Env Vars PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1033
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
GetAdGroup with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.002
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Chromium Browser with Custom User Data Directory
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1497
|
Anomaly
|
Malicious Inno Setup Loader, StealC Stealer, Lokibot, Phantom Stealer
|
2026-06-25
|
|
Windows System User Privilege Discovery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1033
|
Hunting
|
CISA AA23-347A
|
2026-05-13
|
|
Windows Registry Entries Restored Via Reg
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1012
|
Hunting
|
Windows Post-Exploitation, Prestige Ransomware
|
2026-05-13
|
|
Windows Wmic DiskDrive Discovery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1082
|
Anomaly
|
LAMEHUG
|
2026-05-13
|
|
Detect SharpHound File Modifications
|
Sysmon EventID 11
|
T1069.001
T1069.002
T1087.001
T1087.002
T1482
|
TTP
|
BlackSuit Ransomware, Ransomware, Windows Discovery Techniques
|
2026-05-13
|
|
GetDomainGroup with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Registry Entries Exported Via Reg
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1012
|
Hunting
|
Windows Post-Exploitation, Prestige Ransomware, CISA AA23-347A
|
2026-05-13
|
|
Remote System Discovery with Wmic
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1018
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
GetWmiObject User Account with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1087.001
|
Hunting
|
Water Gamayun, Active Directory Discovery, Winter Vivern
|
2026-05-13
|
|
Windows Common Abused Cmd Shell Risk Behavior
|
|
T1016
T1033
T1049
T1059
T1222
T1529
|
Correlation
|
Disabling Security Tools, Windows Post-Exploitation, Microsoft WSUS CVE-2025-59287, FIN7, Qakbot, Windows Defense Evasion Tactics, Sandworm Tools, Azorult, DarkCrystal RAT, Volt Typhoon, Netsh Abuse, CISA AA23-347A
|
2026-05-13
|
|
Windows Wmic Memory Chip Discovery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1082
|
Anomaly
|
LAMEHUG
|
2026-05-13
|
|
Domain Account Discovery with Dsquery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1087.002
|
Anomaly
|
LAMEHUG, Active Directory Discovery
|
2026-05-13
|
|
Windows System Discovery Using Qwinsta
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1033
|
Hunting
|
Qakbot
|
2026-05-13
|
|
Domain Group Discovery With Dsquery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.002
|
Anomaly
|
LAMEHUG, Active Directory Discovery
|
2026-05-13
|
|
Detect SharpHound Command-Line Arguments
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.001
T1069.002
T1087.001
T1087.002
T1482
|
TTP
|
BlackSuit Ransomware, Ransomware, Windows Discovery Techniques
|
2026-05-13
|
|
Wmic Group Discovery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.001
|
Anomaly
|
LAMEHUG, Active Directory Discovery
|
2026-05-13
|
|
Elevated Group Discovery With Wmic
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.002
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Linux Kernel Module Enumeration
|
Sysmon for Linux EventID 1
|
T1014
T1082
|
Anomaly
|
XorDDos, Linux Rootkit
|
2026-05-13
|
|
Network Connection Discovery With Arp
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1049
|
Hunting
|
Windows Post-Exploitation, Active Directory Discovery, Qakbot, Interlock Ransomware, Volt Typhoon, Prestige Ransomware, IcedID
|
2026-08-30
|
|
Detect AzureHound Command-Line Arguments
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.001
T1069.002
T1087.001
T1087.002
T1482
|
TTP
|
Compromised Windows Host, Windows Discovery Techniques
|
2026-05-13
|
|
Windows Chromium Browser No Security Sandbox Process
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1497
|
TTP
|
Malicious Inno Setup Loader, Phantom Stealer
|
2026-06-25
|
|
DSQuery Domain Discovery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1482
|
TTP
|
Domain Trust Discovery, Active Directory Discovery, Compromised Windows Host
|
2026-05-13
|
|
Windows Chromium Browser Launched with Small Window Size
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1497
|
TTP
|
Browser Hijacking
|
2026-05-13
|
|
System Information Discovery Detection
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1082
|
TTP
|
BlankGrabber Stealer, Interlock Ransomware, Lotus Blossom Chrysalis Backdoor, SolarWinds WHD RCE Post Exploitation, Cleo File Transfer Software, NetSupport RMM Tool Abuse, Windows Discovery Techniques, LAMEHUG, Gozi Malware, BlackSuit Ransomware, Medusa Ransomware
|
2026-05-13
|
|
Windows User Discovery Via Net
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1087.001
T1087.002
|
Hunting
|
Medusa Ransomware, Sandworm Tools, Active Directory Discovery
|
2026-08-05
|
|
Windows System User Discovery Via Quser
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1033
|
Hunting
|
Windows Post-Exploitation, Crypto Stealer, Prestige Ransomware
|
2026-05-13
|
|
Web Servers Executing Suspicious Processes
|
Sysmon EventID 1
|
T1082
|
TTP
|
Apache Struts Vulnerability
|
2026-05-13
|
|
Ping Sleep Batch Command
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1497.003
|
Anomaly
|
Meduza Stealer, Void Manticore, WhisperGate, Quasar RAT, Warzone RAT, Gh0st RAT, Data Destruction, BlackByte Ransomware
|
2026-08-11
|
|
Windows Time Based Evasion
|
Sysmon EventID 1, CrowdStrike ProcessRollup2
|
T1497.003
|
TTP
|
BlankGrabber Stealer, NjRAT
|
2026-05-13
|
|
Get ADUser with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1087.002
|
Hunting
|
Active Directory Discovery, CISA AA23-347A
|
2026-05-13
|
|
Remote System Discovery with Dsquery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1018
|
Anomaly
|
LAMEHUG, Active Directory Discovery
|
2026-05-13
|
|
Windows Password Policy Discovery with Net
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1201
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Detect SharpHound Usage
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.001
T1069.002
T1087.001
T1087.002
T1482
|
TTP
|
Ransomware, Windows Discovery Techniques
|
2026-05-13
|
|
Windows System Discovery Using ldap Nslookup
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1033
|
Anomaly
|
Qakbot
|
2026-05-13
|
|
MacOS List Firewall Rules
|
Osquery Results
|
T1016
|
Anomaly
|
Network Discovery
|
2026-05-13
|
|
Domain Controller Discovery with Wmic
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1018
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Information Discovery Fsutil
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1082
|
Anomaly
|
Windows Post-Exploitation, Prestige Ransomware
|
2026-05-13
|
|
GetNetTcpconnection with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1049
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Chromium process Launched with Disable Popup Blocking
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1497
|
Anomaly
|
Browser Hijacking
|
2026-05-13
|
|
GetWmiObject Ds Computer with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1018
|
Anomaly
|
Active Directory Discovery
|
2026-05-13
|
|
Windows System Network Connections Discovery Netsh
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1049
|
Anomaly
|
Windows Post-Exploitation, BlankGrabber Stealer, VIP Keylogger, Snake Keylogger, Prestige Ransomware, Phantom Stealer
|
2026-06-25
|
|
Get-ForestTrust with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1482
|
TTP
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Net System Service Discovery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1007
|
Hunting
|
LAMEHUG, Gh0st RAT
|
2026-05-13
|
|
Windows Network Connection Discovery Via Net
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1049
|
Hunting
|
Azorult, Windows Post-Exploitation, Active Directory Discovery, Prestige Ransomware
|
2026-05-13
|
|
Windows Network Sniffing Tool Executed
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1040
|
Anomaly
|
Credential Dumping, Network Discovery, Suspicious Command-Line Executions, Windows Discovery Techniques, Data Exfiltration
|
2026-07-30
|
|
GetWmiObject Ds Group with PowerShell
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.002
|
Anomaly
|
Active Directory Discovery
|
2026-05-13
|
|
Windows Post Exploitation Risk Behavior
|
|
T1003
T1012
T1016
T1049
T1069
T1082
T1115
T1552
|
Correlation
|
Windows Post-Exploitation
|
2026-05-13
|
|
Windows Sensitive Group Discovery With Net
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.002
|
Anomaly
|
Microsoft WSUS CVE-2025-59287, Active Directory Discovery, Volt Typhoon, BlackSuit Ransomware, IcedID, Rhysida Ransomware
|
2026-05-13
|
|
Network Discovery Using Route Windows App
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1016.001
|
Hunting
|
Windows Post-Exploitation, Active Directory Discovery, Qakbot, Prestige Ransomware, CISA AA22-277A
|
2026-05-13
|
|
Windows Wmic CPU Discovery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1082
|
Anomaly
|
LAMEHUG
|
2026-05-13
|
|
System User Discovery With Whoami
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1033
|
Hunting
|
Active Directory Discovery, Qakbot, Lotus Blossom Chrysalis Backdoor, Winter Vivern, PHP-CGI RCE Attack on Japanese Organizations, LAMEHUG, Rhysida Ransomware, CISA AA23-347A
|
2026-08-30
|
|
Get WMIObject Group Discovery
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1069.001
|
Hunting
|
Active Directory Discovery
|
2026-05-13
|
|
MacOS Network Share Discovery
|
Osquery Results
|
T1135
|
Anomaly
|
MacOS Post-Exploitation
|
2026-05-13
|
|
Windows Network Share Interaction Via Net
|
Sysmon EventID 1, CrowdStrike ProcessRollup2, Windows Event Log Security 4688
|
T1039
T1135
|
Hunting
|
Active Directory Privilege Escalation, Network Discovery, Active Directory Discovery
|
2026-05-13
|
|
Internal Horizontal Port Scan
|
AWS CloudWatchLogs VPCflow, Cisco Secure Firewall Threat Defense Connection Event
|
T1046
|
TTP
|
China-Nexus Threat Activity, Scattered Lapsus$ Hunters, Network Discovery, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|
|
Cisco SNMP Community String Configuration Changes
|
Cisco IOS Logs
|
T1040
T1552
T1685
|
Anomaly
|
Cisco Smart Install Remote Code Execution CVE-2018-0171
|
2026-05-13
|
|
Internal Vulnerability Scan
|
|
T1046
T1595.002
|
TTP
|
Scattered Lapsus$ Hunters, Network Discovery
|
2026-05-13
|
|
Internal Horizontal Port Scan NMAP Top 20
|
AWS CloudWatchLogs VPCflow, Cisco Secure Firewall Threat Defense Connection Event
|
T1046
|
TTP
|
China-Nexus Threat Activity, Scattered Lapsus$ Hunters, Network Discovery, Cisco Secure Firewall Threat Defense Analytics
|
2026-09-08
|
|
Internal Vertical Port Scan
|
AWS CloudWatchLogs VPCflow, Cisco Secure Firewall Threat Defense Connection Event
|
T1046
|
TTP
|
China-Nexus Threat Activity, Scattered Lapsus$ Hunters, Network Discovery, Cisco Secure Firewall Threat Defense Analytics
|
2026-05-13
|